Vulnerability scanning
769 rows from 206 repositories
Automated checks for known-bad patterns and known-bad versions.
What Vulnerability scanning skills agree on
209 skill files read, by 223 of the 238 authors on this shelf whose files we hold, 2026-09-06
The middle one of the 31 measured here is ~1.7k tokens long, counted with cl100k_base
Counted by distinct author, so one author publishing three of these counts once. Where a claim sits in fewer files than authors, that is said: a claim held by forty authors across three files is one file people copied, not forty people who agreed. Near-identical wordings are grouped and the other wordings are shown, so the grouping is yours to check.
What they tell the agent to do
- Fix critical findings immediately21 of 223 in 14 filesalso worded as Fix Critical and High findings; Address critical and high findings immediately
- Fix high findings before production18 of 223 in 12 filesalso worded as Fix Critical and High findings before release; fix high-risk findings before production deployment
- Check and install AgentShield before scanning18 of 223 in 12 filesalso worded as check AgentShield is installed before scanning; Verify AgentShield is installed before scanning
- Scaffold a secure configuration with init16 of 223 in 10 filesalso worded as Scaffold secure config with init; Scaffold secure configuration with init
- Add the AgentShield GitHub Action to CI16 of 223 in 10 filesalso worded as Add the AgentShield action to CI; add the GitHub Action to the CI pipeline
- Run the three-agent opus pipeline for deeper analysis14 of 223 in 8 filesalso worded as run the three-agent deep analysis for deeper review; Run the three-agent deep analysis pipeline
- Apply safe auto-fixes only14 of 223 in 8 filesalso worded as apply auto-fixes only to auto-fixable findings; Apply only auto-fixable fixes automatically
- Use JSON output for CI/CD integration13 of 223 in 7 filesalso worded as use JSON output format for CI integration; Use JSON format for CI integration
- Filter findings with a minimum severity12 of 223 in 10 filesalso worded as Filter results by minimum severity; Filter findings to specified severity levels
- Classify each finding by severity10 of 223also worded as Classify findings by severity and apply the disposition; Classify findings by severity
- Use parameterized queries for all database access10 of 223 in 9 filesalso worded as Use parameterized queries for all SQL; Parameterize every database query
- Write tests before writing the rule9 of 223 in 4 filesalso worded as Write test files before writing the rule; Write test cases before writing the rule
- Validate all user inputs9 of 223also worded as Verify all user inputs are validated and sanitized; Validate all input server-side
- Scan the .claude/ configuration directory8 of 223 in 4 filesalso worded as Scan the project's .claude/ configuration directory; Run the scan against the .claude directory
- Set ANTHROPIC_API_KEY before opus analysis8 of 223 in 4 filesalso worded as Export ANTHROPIC_API_KEY before opus analysis; Set ANTHROPIC_API_KEY before deep analysis
What they tell it not to do
- Never modify manual-only suggestions20 of 223 in 14 filesalso worded as Never modify manual-only suggestions during auto-fix; Do not modify manual-only suggestions
- Never write a rule without tests15 of 223 in 7 filesalso worded as Writing a rule without tests; Never write a rule without tests
- Never hardcode secrets15 of 223 in 14 filesalso worded as Never hardcode secrets or real private data; Never hardcode secrets in source
- Never concatenate user input into SQL strings14 of 223 in 11 filesalso worded as Never interpolate user input into SQL; Never concatenate user input into queries
- Do not skip any workflow steps8 of 223 in 3 filesalso worded as Do not skip any workflow steps; Do not skip workflow steps
- Never commit the .env file7 of 223also worded as Never commit .env files, API keys, or credentials; Never commit real .env files to version control
- Never expose stack traces in production6 of 223 in 5 filesalso worded as Never expose stack traces in error responses; Never expose stack traces or internal details to users
- Never use todook or todoruleid annotations6 of 223 in 2 filesalso worded as Never use todook or todoruleid annotations
- Never interpolate user input into raw SQL6 of 223also worded as Never interpolate user input into SQL strings; Never interpolate user input into queries
- Do not auto-fix beyond auto-fixable findings5 of 223 in 3 filesalso worded as don't auto-fix findings; Do not auto-fix findings
What they expect to be installed
- semgrep51 of 223 in 47 files
- npm audit35 of 223 in 34 files
- trivy31 of 223 in 29 files
- CodeQL25 of 223 in 23 files
- gitleaks25 of 223
- npm24 of 223 in 17 files
- pip-audit22 of 223 in 21 files
- git20 of 223 in 18 files
- npx ecc-agentshield19 of 223 in 13 files
- Snyk15 of 223 in 14 files
What they ask it to produce
- HTML security report18 of 223 in 12 filesalso worded as HTML report; security-report.html
- Security scan report13 of 223 in 12 filesalso worded as JSON security scan report; Security Scan Results markdown report
- Scaffolded settings.json, CLAUDE.md, and mcp.json10 of 223 in 6 filesalso worded as scaffolded settings.json, CLAUDE.md, mcp.json; Scaffolded settings.json
- Semgrep rule YAML file9 of 223 in 4 filesalso worded as Ported Semgrep rule YAML; Custom Semgrep rule YAML
- JSON report for CI/CD9 of 223 in 5 filesalso worded as JSON audit report for CI; JSON report for CI integration
- Test file with ruleid and ok annotations7 of 223 in 3 filesalso worded as Annotated test file with ruleid and ok markers
- Scaffolded secure configuration files7 of 223 in 5 filesalso worded as Scaffolded secure config files; Scaffolded secure .claude/ config files
- Scan report with severity grade7 of 223 in 3 filesalso worded as colored scan report with severity grade; security scan report grouped by severity
When Vulnerability scanning authors say to reach for one
The situations these authors wrote into their own files, counted out of the same 223 authors, with the skills that name each one
- During periodic security hygiene checks21 of 223 in 15 files
- Security scan
- and 10 more on this shelf
- Before committing configuration changes20 of 223 in 14 files
- Security scan
- and 10 more on this shelf
- User asks to scan for vulnerabilities20 of 223 in 19 files
- Security review
- Auditing npm dependencies
- Owasp audit
- Tob semgrep
- Semgrep
- and 1 more on this shelf
- Onboarding to a repository with existing configs16 of 223 in 10 files
- Security scan
- and 10 more on this shelf
- When setting up a new project11 of 223 in 9 files
- Security scan
- and 10 more on this shelf
- Reviewing pull requests8 of 223 in 6 files
How Vulnerability scanning skills are built
687 skill directories by 197 authors, read from their repositories’ own file trees 2026-08-05
The middle bundle among those shipping files is 3 files, 24.1 KB beside SKILL.md
Counted by distinct author, same as above, so one author publishing forty template copies counts once. SKILL.md itself is not counted as a file, so a single-file skill is one where that file is the whole skill.
The shape
- SKILL.md is the whole skill82 of 197 authors, 351 of 687 skills
- files ship beside it115 of 197 authors, 336 of 687 skills
- executable scripts ship inside50 of 197 authors, 166 of 687 skills
The folders they converge on
- references/77 of 197 authors, 240 of 687 skills
- scripts/46 of 197 authors, 166 of 687 skills
- assets/15 of 197 authors, 76 of 687 skills
- evals/9 of 197 authors, 15 of 687 skills
- examples/7 of 197 authors, 7 of 687 skills
- agents/6 of 197 authors, 9 of 687 skills
atgreen/secscan-skill Skill
51★Mirror of https://cave.moxielogic.com/atgreen/secscan-skill
mythos-agent/mythos-agent/io.github.mythos-agent/mythos-agent MCP server
39★ repoOpen-source AI security agent: SAST, DAST, and policy-as-code over MCP.
myclaude-sh/myclaude-creator-engine/.claude/skills/aegis Skill
24★ repoThe creation pipeline for Claude Code products — research, create, validate, publish. 13 types, 20 quality patterns, zero coding required.
b3sty191/b3sty-skill Skill
no license8★b3sty RedM/FiveM Lua Codex skill
snyk/saw-mcp/io.github.snyk/saw-mcp MCP server
7★ repoMCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage
tinoimammp/vantage-security-agent/skills/vantage Skill
4★ repoAI-powered vulnerability scanner plugin for Claude Code with 28 agents statically scan web & mobile repos for OWASP Top 10 / Mobile Top 10 vulnerabilities, validate findings, and optionally auto-fix them. No live requests, ever.
cyber-sorted/skills-pro/cybersorted Skill
no license3★ repoProfessional security and enterprise architecture advisory skills for Claude Code
xAmirHamza77/PenKit51/assistant-skills/chatgpt/penkit51-ai Skill
no license2★ repoPenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.
Skyrxin/sast-mcp-server/io.github.Skyrxin/sast-mcp-server MCP server
2★ repo11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations
Dolphinllc/claude-security-skills/skills/defensive/genai/anthropic-sdk-security-scan Skill
1★ repoDefensive security skills for Claude Code and the Claude Agent SDK — web applications and generative AI systems.
riz007/architect-os/skills/aos-audit Skill
1★ repoAI-native software engineering operating system for modern application architecture, scaffolding, and AI-assisted development.
reasonless-throne486/sast-skills/sast-files/.agents/skills/sast-analysis Skill
0★ repoScan codebases for security flaws with LLM agent skills that turn Claude Code, Cursor, and other assistants into SAST scanners
ayman-benmada/owasp-security-audit/skills/security-audit Skill
no license0★ repoOWASP Top 10 (2025) security audit plugin for Claude Code and Cursor. Stack-aware scanning that produces a complete vulnerability report.
omonuj/claude-horizon-skills/skills/fanout-cve-rollout/fanout-cve-iteration-loop Skill
no license0★ repoClaude Code Agent Skills for building, red-teaming and tuning agentic RL evaluation environments — a four-skill pattern (guardian, validation-debugger, score-tuner, iteration-loop) plus a 24-point adversarial reviewer.
kpatryk/skills/skills/bandit Skill
0★ repoAI skills
sokratisg/trivy-security-scan/skills/trivy-security-scan Skill
0★ repoAgent-neutral Trivy security scanning skill for local vulnerability, misconfiguration, secret, and license scans.
Hermes skill local web security scan
web3blind/hermes-skill-local-web-security-scan Skill
no license0★Local Web Security Scan
sjsylee/skills-hub/skills/codebase-security-audit Skill
0★ repo바이브 코딩에 규율을 입히는 에이전트 스킬 모음 · Agent skills that bring discipline to vibe coding. Install: npx skills add sjsylee/skills-hub
weiseer/cve-cache-mcp/io.github.weiseer/cve-cache MCP server
no license0★ repoRecent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
tody-agent/codymaster/.agent/skills/xss-html-injection Skill
no license49★ repoVibe Coding Framework - Full SaaS Development Team from A-Z with Brain, Self Improvement, Auto Development
xAmirHamza77/PenKit51/assistant-skills/claude/penkit51-ai Skill
no license2★ repoPenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.
Pwnote/skills/skills/pwnote-cve-research Skill
2★ repoAI agent skills for Pwnote Pentest Notebook
Dolphinllc/claude-security-skills/skills/defensive/genai/langchain-security-scan Skill
1★ repoDefensive security skills for Claude Code and the Claude Agent SDK — web applications and generative AI systems.
reasonless-throne486/sast-skills/sast-files/.agents/skills/sast-businesslogic Skill
0★ repoScan codebases for security flaws with LLM agent skills that turn Claude Code, Cursor, and other assistants into SAST scanners
omonuj/claude-horizon-skills/skills/fanout-cve-rollout/fanout-cve-score-tuner Skill
no license0★ repoClaude Code Agent Skills for building, red-teaming and tuning agentic RL evaluation environments — a four-skill pattern (guardian, validation-debugger, score-tuner, iteration-loop) plus a 24-point adversarial reviewer.
jpoindexter/security-skills/sast-scan Skill
0★ repoAgent skills for running security scans — secret scanning (gitleaks), dependency CVE audit (npm/cargo/osv), SAST (semgrep), and a composed pre-release gate. Grounded SKILL.md runbooks for Vanta / Claude Code / any skill-aware agent. MIT.
Frontend mobile security xss scan
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/frontend-mobile-security-xss-scan Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/sast-configuration Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Security scanning security sast
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/security-scanning-security-sast Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/semgrep-rule-creator Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/semgrep-rule-variant-creator Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/sql-injection-testing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/xss-html-injection Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Frontend mobile security xss scan
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/frontend-mobile-security-xss-scan Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/sast-configuration Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Security scanning security sast
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/security-scanning-security-sast Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/semgrep-rule-creator Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/semgrep-rule-variant-creator Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/sql-injection-testing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/xss-html-injection Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-secure-app-builder/skills/sast-configuration Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-security-engineer/skills/sast-configuration Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Frontend mobile security xss scan
sickn33/agentic-awesome-skills/skills/frontend-mobile-security-xss-scan Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/sast-configuration Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
Security scanning security sast
sickn33/agentic-awesome-skills/skills/security-scanning-security-sast Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/semgrep-rule-creator Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/semgrep-rule-variant-creator Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/sql-injection-testing Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
sickn33/agentic-awesome-skills/skills/xss-html-injection Skill
44,658★ repoAAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.
wshobson/agents/plugins/security-scanning/skills/sast-configuration Skill
38,701★ repoMulti-harness agentic plugin marketplace for Claude Code, Codex CLI, Cursor, OpenCode, GitHub Copilot, and Gemini CLI
github/awesome-copilot/skills/security-review Skill
37,897★ repoCommunity-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot.
alirezarezvani/claude-skills/engineering-team/skills/senior-secops Skill
24,478★ repo345 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.
alirezarezvani/claude-skills/engineering/security-guidance/skills/security-guidance Skill
24,478★ repo345 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.
eigent-ai/eigent/resources/example-skills/skill-security-auditor Skill
15,013★ repoEigent: The Open Source Cowork Desktop - Local and Free Alternative to Claude Cowork and Codex
Jeffallan/claude-skills/skills/code-reviewer Skill
10,966★ repo66 Specialized Skills for Full-Stack Developers. Transform Claude Code into your expert pair programmer.
trailofbits/skills/plugins/semgrep-rule-creator/skills/semgrep-rule-creator Skill
6,559★ repoTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
trailofbits/skills/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator Skill
6,559★ repoTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
trailofbits/skills/plugins/static-analysis/skills/semgrep Skill
6,559★ repoTrail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
zebbern/claude-code-guide/skills/code-vuln-audit Skill
4,568★ repoClaude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks go from beginner to power user!
zebbern/claude-code-guide/skills/secure-code-review Skill
4,568★ repoClaude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks go from beginner to power user!